Showing posts with label LinkedIn. Show all posts
Showing posts with label LinkedIn. Show all posts

Monday, 28 November 2016

Beware! Ransomware Spreading Via JPG Files on Facebook, LinkedIn

Internet users are targeted by hackers with the intention to get money from them by all means. Usually, malware is installed on computers through browsers or OS security vulnerabilities and users fall victims to ransomware. But these attacks can be avoided with the right antivirus program an if people are more careful and don’t click on dubious links and banners. However, they tend to forget that sometimes, the social networks themselves can be the source of the problem, because they also have vulnerabilities that can be exploited by hackers.


The malware was first reported by Check Point, an Israeli security firm. According to the report, which takes advantage of vulnerabilities in the way Facebook, LinkedIn and other social networks handle images and it forces the system to download maliciously coded image file. Locky ransomware kicks into action when users access the file.

Opening the file will allow the ransomware called “Locky” to infect the unit, which basically holds the computer hostage. In order for the users to get the key to use their computers again, they will need to pay about $365 in bitcoin form. At least, this is what the people responsible for the malware are demanding.

Ars Technica reports that the malware has been quite prominent during the past year, with many computers becoming infected due to Word documents and the usual spammy email messages. This development involving social media images, however, is an entirely new trend that provides dangerous precedence for other malicious individuals.

After downloading that maliciously coded image file and users open it, their system is hijacked and files are encrypted, and in order to unlock them, victims must pay up (the key costs £294, $365). Back in February, security researcher Lawrence Abrams was warning that “When Locky encrypts a file it will rename the file to the format [unique_id][identifier].locky”, “So when test.jpg is encrypted it would be renamed to something like F67091F1D24A922B1A7FC27E19A9D9BC.locky. The unique ID and other information will also be embedded into the end of the encrypted file.”

The only way to avoid the actual Locky code, which has been around for almost a year, is to be aware of it and to not open the file. But usually, people who use social networks trust them and don’t realize that they open their doors to hackers who exploit flaws in these websites. Both Facebook and LinkedIn have been contacted by the Israeli security firm in September, but it’s not sure if the developers have the situation under control.

Check the demonstration below:




Tuesday, 7 June 2016

It's Time to Strengthen Your Passwords: Even Mark Zuckerberg's Account Got Hacked!!!

Mark Zuckerberg's biggest social network presence is undoubtedly on Facebook, but he has other accounts, too -- and he's learning the hard way that those accounts are just as sensitive. Facebook CEO Mark Zuckerberg’s Twitter and Pinterest accounts were recently compromised, likely as a result of a mass LinkedIn password hack. (If you have not already done so, go change your LinkedIn password.) The fact that Zuckerberg can fall victim to a security breach is not a surprise. What is a surprise is how bad his password was: according to the hackers, his password was “dadada.”

It’s a comically bad password. It doesn’t have special characters or numbers. It doesn’t even have an uppercase letter. It’s only two letters, just repeated. It’s very, very bad.

Neither Zuckerberg nor Facebook have commented on the hack or confirmed the password, but if this is indeed accurate, “dadada” eludes nearly every characteristic of a strong password. The hack also would suggest he used the same password his Pinterest and Twitter accounts, another failing.

The age-old advice to not re-use passwords is particularly timely at the moment. Beyond the LinkedIn theft, there were also recent leaks of 360 million email addresses and passwords belonging to users of MySpace.com. Since May, the website Leakedsource.com, which sells access to the stolen information, has added close to one billion records to its database The publicity around the hack of Mr. Zuckerberg’s accounts may prompt other attackers to take advantage of the stolen data in the same way.
Strengthen your password. Here are few tips to do so.
— Make your password long. The recommended minimum is eight characters, but 14 is better and 25 is even better than that. Some services have character limits on passwords, though.

— Use combinations of letters and numbers, upper and lower case and symbols such as the exclamation mark. Some services won't let you do all of that, but try to vary it as much as you can. "PaSsWoRd!43" is far better than "password43."

— Avoid words that are in dictionaries, even if you add numbers and symbols. There are programs that can crack passwords by going through databases of known words. One trick is to add numbers in the middle of a word — as in "pas123swor456d" instead of "password123456." Another is to think of a sentence and use just the first letter of each word — as in "tqbfjotld" for "the quick brown fox jumps over the lazy dog."

— Substitute characters. For instance, use the number zero instead of the letter O, or replace the S with a dollar sign.

— Avoid easy-to-guess words, even if they aren't in the dictionary. You shouldn't use your name, company name or hometown, for instance. Avoid pets and relatives' names, too. Likewise, avoid things that can be looked up, such as your birthday or ZIP code. But you might use that as part of a complex password. Try reversing your ZIP code or phone number and insert that into a string of letters. As a reminder, you should also avoid "password" as the password, or consecutive keys on the keyboard, such as "1234" or "qwerty."

— Never reuse passwords on other accounts — with two exceptions. Over the years, I've managed to create hundreds of accounts. Many are for one-time use, such as when a newspaper website requires me to register to read the full story. It's OK to use simple passwords and repeat them in those types of situations, as long as the password isn't unlocking features that involve credit cards or posting on a message board. That will let you focus on keeping passwords to the more essential accounts strong.